HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
During installation, installed file permissions are set to allow anyone to modify those files.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Connections | Hcltech | 7.0 (including) | 7.0 (including) | 
| Connections | Hcltech | 8.0 (including) | 8.0 (including) | 
| Connections | Hcltech | 8.0-cumulative_release1 (including) | 8.0-cumulative_release1 (including) | 
| Connections | Hcltech | 8.0-cumulative_release2 (including) | 8.0-cumulative_release2 (including) | 
| Connections | Hcltech | 8.0-cumulative_release3 (including) | 8.0-cumulative_release3 (including) | 
| Connections | Hcltech | 8.0-cumulative_release4 (including) | 8.0-cumulative_release4 (including) | 
| Connections | Hcltech | 8.0-cumulative_release5 (including) | 8.0-cumulative_release5 (including) | 
| Connections | Hcltech | 8.0-cumulative_release6 (including) | 8.0-cumulative_release6 (including) | 
| Connections | Hcltech | 8.0-cumulative_release7 (including) | 8.0-cumulative_release7 (including) |